Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 367 277

Количество 367 277

github логотип

GHSA-457j-x7h3-8hjh

больше 1 года назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7.

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-457j-cjp6-q7h3

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-457g-xg5v-227f

больше 2 лет назад

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-457g-f88f-3329

больше 4 лет назад

Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-457f-xp3m-rv66

больше 4 лет назад

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-457f-wg3h-7vw8

больше 4 лет назад

The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with the privileges of an authenticated administrator user.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-457f-qv6r-jcjg

около 4 лет назад

A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process. (FG-VD-22-052, FG-VD-22-056)

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-457f-q7w2-wmhh

больше 4 лет назад

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

EPSS: Средний
github логотип

GHSA-457f-pcj5-v75v

около 1 года назад

A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-457f-g7c4-56q4

больше 4 лет назад

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caused by using possible old value of msg mask table count while copying masks to userspace.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-457f-c77p-7wc3

больше 3 лет назад

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-457c-p98r-9wg6

25 дней назад

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-4579-7jx6-x8r3

больше 4 лет назад

Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.

EPSS: Низкий
github логотип

GHSA-4578-w77v-3r84

13 дней назад

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4578-6gjh-f2jm

около 1 года назад

Mattermost allows an unauthorized Guest user access to Playbook

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4576-pgh2-g34j

больше 2 лет назад

derhansen/sf_event_mgt vulnerable to Broken Access Control in Backend Module

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-4576-cf38-77f2

больше 4 лет назад

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-4574-x3wr-77rh

почти 4 года назад

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4574-w5wx-78f9

6 месяцев назад

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through <= 1.3.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-4574-qv3w-fcmg

около 5 лет назад

Deserialization of Untrusted Data in codeception/codeception

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-457j-x7h3-8hjh

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lee Blue Cart66 Cloud allows Reflected XSS. This issue affects Cart66 Cloud: from n/a through 2.3.7.

CVSS3: 7.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-457j-cjp6-q7h3

Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-457g-xg5v-227f

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Russell Jamieson Footer Putter allows Stored XSS.This issue affects Footer Putter: from n/a through 1.17.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-457g-f88f-3329

Directory traversal vulnerability in AttacheCase for Java 0.60 and earlier, AttacheCase Lite 1.4.6 and earlier, and AttacheCase Pro 1.5.7 and earlier allows remote attackers to read arbitrary files via specially crafted ATC file.

CVSS3: 5.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-457f-xp3m-rv66

It was discovered that a world-readable log file belonging to Candlepin component of Red Hat Satellite 6.4 leaked the credentials of the Candlepin database. A malicious user with local access to a Satellite host can use those credentials to modify the database and prevent Satellite from fetching package updates, thus preventing all Satellite hosts from accessing those updates.

CVSS3: 7.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-457f-wg3h-7vw8

The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with the privileges of an authenticated administrator user.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-457f-qv6r-jcjg

A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application contains a stack corruption vulnerability while parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process. (FG-VD-22-052, FG-VD-22-056)

CVSS3: 5.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-457f-q7w2-wmhh

A Directory Traversal vulnerability exits in Processwire CMS before 2.7.1 via the download parameter to index.php.

16%
Средний
больше 4 лет назад
github логотип
GHSA-457f-pcj5-v75v

A vulnerability has been found in TOTOLINK EX1200T up to 4.1.2cu.5232_B20210713 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /boafrm/formWsc of the component HTTP POST Request Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

CVSS3: 8.8
1%
Низкий
около 1 года назад
github логотип
GHSA-457f-g7c4-56q4

In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, Out of bound mask range access caused by using possible old value of msg mask table count while copying masks to userspace.

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-457f-c77p-7wc3

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-457c-p98r-9wg6

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to a buffer overflow from improperly validating client data. By sending malformed requests to one of the host servers, a remote attacker could leverage this vulnerability to cause a denial-of-server (DoS) for that server.

CVSS3: 7.5
0%
Низкий
25 дней назад
github логотип
GHSA-4579-7jx6-x8r3

Unspecified vulnerability in the Oracle Communications Diameter Signaling Router component in Oracle Communications Applications 3.x, 4.x, and 5.0 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Signaling - DPI.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-4578-w77v-3r84

NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.

CVSS3: 8.1
0%
Низкий
13 дней назад
github логотип
GHSA-4578-6gjh-f2jm

Mattermost allows an unauthorized Guest user access to Playbook

CVSS3: 4.3
0%
Низкий
около 1 года назад
github логотип
GHSA-4576-pgh2-g34j

derhansen/sf_event_mgt vulnerable to Broken Access Control in Backend Module

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-4576-cf38-77f2

nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive CPU usage. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

CVSS3: 7.5
12%
Средний
больше 4 лет назад
github логотип
GHSA-4574-x3wr-77rh

Tenda AC10 V15.03.06.23 contains a Stack overflow vulnerability via /goform/formSetFirewallCfg.

CVSS3: 9.8
1%
Низкий
почти 4 года назад
github логотип
GHSA-4574-w5wx-78f9

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Don Peppe donpeppe allows PHP Local File Inclusion.This issue affects Don Peppe: from n/a through <= 1.3.

CVSS3: 8.1
1%
Низкий
6 месяцев назад
github логотип
GHSA-4574-qv3w-fcmg

Deserialization of Untrusted Data in codeception/codeception

CVSS3: 9.8
3%
Низкий
около 5 лет назад

Уязвимостей на страницу